likefire[.]vip
Перевірка домену likefire.vip на фішинг і безпеку
“Aiinvest: One-Stop Global Investment Platform | Forex | Commodities | Stocks ...”
likefire.vip — Останній відомий активний (HTTP 200). Тип шахрайства: Investment Scam. Зведення доказів: VT 3/91 (Bfore.Ai PreCrime, Kaspersky, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 88/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy first observed likefire.vip on Jun 23, 2026. Positive findings were recorded by VirusTotal, MetaMask, and SEAL. Evidence score: 88/100.
VirusTotal recorded 3 detections among 91 engines: Bfore.Ai PreCrime, Kaspersky, SOCRadar on Jul 12, 2026 at 15:30 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 14:20 UTC. AlienVault OTX listed 16 community pulse references (not vendor detections) on Jul 12, 2026 at 15:31 UTC. URLQuery recorded no positive detection on Jun 23, 2026 at 17:16 UTC. Google Safe Browsing returned no flag on Jul 12, 2026 at 15:30 UTC. URLScan completed without a malicious verdict on Jun 24, 2026 at 08:10 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:18 UTC. Registration records list Gname.com Pte. Ltd. as the registrar and Sep 11, 2025 as the registration date. At collection time, the domain resolved to 104.21.59.21. Captured page title: “Aiinvest: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurrencies | Gold | Oil”. PhishDestroy classified the observed content as Investment Scam. DOM analysis completed on Jun 23, 2026 at 18:20 UTC; stored DOM score 88/100. IoC extraction completed on Jul 29, 2026 at 01:59 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis13.07.2026
Analysis of the domain likefire.vip indicates it is actively operating as an investment scam platform, specifically targeting individuals interested in forex, commodities, stocks, indices, cryptocurrencies, gold, and oil trading. The domain was registered on September 11, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. Infrastructure analysis reveals the site is hosted behind Cloudflare (AS13335), resolving to the IP address 104.21.59.21, located in the United States. The domain employs Cloudflare nameservers (leah.ns.cloudflare.com and mark.ns.cloudflare.com) and utilizes technologies including Vue.js, HSTS, and HTTP/3, which are consistent with modern phishing infrastructure designed to evade detection and enhance perceived legitimacy. The page title, 'Aiinvest: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurrencies | Gold | Oil,' explicitly positions the site as a financial trading platform, a common tactic in investment scams to lure victims with promises of high returns. The domain has been flagged by three security blocklists and appears in 16 threat intelligence pulses on AlienVault OTX, further corroborating its malicious classification. Gridinsoft assigns the domain a trust score of 0/100, indicating a complete lack of credibility. While VirusTotal reports that 3 out of 91 security vendors have detected the domain as malicious, this number may underrepresent the true risk due to the use of evasion techniques such as Cloudflare proxying. Defenders are advised to treat this domain as an active threat. Network-level blocking of the IP 104.21.59.21 and domain likefire.vip is recommended, along with monitoring for related infrastructure registered through Gname.com Pte. Ltd. or utilizing similar Cloudflare-hosted configurations.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
ICANN отримала гроші. Підзвітність так і не з’явилася.
Для цього gTLD зазначений вище реєстратор працює за договором з ICANN. ICANN стягує щорічні, змінні та транзакційні збори, пов’язані з реєстраціями, продовженнями та трансферами.
Акредитація: монетизована. Підзвітність: будь ласка, перевірте пізніше.
Далі починається магія: ICANN пише RAA §3.18, реєстратор розслідує зловживання у власній клієнтській базі, а жертви безкоштовно надають докази, поки кожна ланка чекає, що діяти почне хтось інший. Якщо це допомагає жертвам почуватися безпечніше — чудово: рахунок спрацював.
Технології · 5 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of likefire.vip · checked Jul 12, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Про цей звіт: likefire.vip
Цей звіт представляє останні збережені докази, доступні PhishDestroy. Позначки часу джерела відображаються, якщо вони доступні; доступність і рішення постачальника можуть змінитися після отримання.
Захоплений сайт відображав назву сторінки “Aiinvest: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocu...”.
Станом на 07.08.2026 likefire.vip було виявлено системами безпеки 3.
Якщо ви вважаєте, що цей список є неточним, подати апеляцію. Щоб дізнатися про нашу методологію, відвідайте Сторінка поширених запитань.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога